Back to Feed
Threat IntelligenceAug 27, 2026

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories

Weekly threats report: IoT botnet, water system targeting, SharePoint RCE, and phishing frameworks.

Summary

This week's ThreatsDay bulletin highlights a 296K-strong IoT botnet, over 100 water systems targeted, and a SharePoint RCE chain. It also details a sophisticated phishing framework called JWR that allows live operator control of victim sessions, and the use of trojanized productivity apps to deliver malware. ReliaQuest also confirmed a failed extortion attempt via social engineering and MFA push abuse.

Full text

ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories Ravie LakshmananAug 27, 2026Hacking News / Cybersecurity News A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different tricks, same advantage: attackers keep finding places where trust is cheap and friction is low. That sets the tone. Here’s the full list of what surfaced this week. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Social engineering attempt fails ReliaQuest Targeted in Failed Extortion Attack Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. The incident took place on August 22, 2026. "The threat actor registered a lookalike domain and stood up a fake ReliaQuest single sign-on (SSO) page behind a content delivery network," the company said. "The threat actor then called multiple ReliaQuest teammates, each time posing as a security employee by name in an attempt to steer them towards the fake page. One teammate entered their password and approved the push notification on their phone. That handed the attacker a brief session on our identity dashboard." ReliaQuest said the extent of the access was view only, and that no applications or systems were accessed, and no customer data was ever touched. Although the company did not attribute the incident to a particular threat actor, it noted the playbook aligns with tactics adopted by ShinyHunters and other extortion crews, such as "an impersonation call, a throwaway lookalike domain registered and burned within the hour, a harvesting page behind a content delivery network, MFA push abuse, and a rapid attempt to enroll a new authenticator." The development comes as ShinyHunters listed the company on its dark web portal. Last week, ReliaQuest said it's tracking a ShinyHunters campaign using domains that follow the "company[.]claims" pattern, including "reliaquest[.]claims." Trojanized productivity apps Fake Websites Deliver Malware Fake websites advertising productivity software are being used to lure users into downloading a deceptively functioning program that contains malware. The Electron-based applications, such as Kitchen Canvas, Food or Meal Formula, DocConvertWizard, and other PDF conversion tools under different names, gain the ability to dynamically execute injected scripts and access desktop capture functionality through Electron APIs. Live operator-driven phishing JWR Phishing Framework Spotted An undocumented phishing framework, internally branded "JWR" by its developer, is designed to convincingly impersonate checkout and login pages across major payment and shopping platforms. "The client engine of the JWR phishing framework is a real-time, operator-driven system that, rather than merely logging form submissions like a static credential-stealing page, keeps an AES-CTR encrypted WebSocket open to the threat actor so they can steer each victim's session live," Cisco Talos said. "The victim data targeted by the actor using JWR extends well beyond payment data, encompassing identity documents, Social Security numbers, passport and driver's license images, website and PayPal credentials, 2FA codes, and full device fingerprints, all committed to the actor's server once a session ends." The JWR phishing framework is assessed to be a variant of The Outsider phishing-as-a-service (PhaaS) platform, based on several similarities in the client engine scripts and functionalities of the two PhaaS platforms. Android fraud bot for rent Octagon Android Banking Malware Sold on Underground Forums Cybersecurity researchers have disclosed Octagon, a previously undocumented Android on-device fraud bot sold as malware-as-a-service (MaaS) by the Russian-speaking actor AndroidKitKat. "The operator advertises Octagon for $1,400 a month, giving buyers accessibility overlays, hidden VNC, SMS and one-time password interception, unlock-pattern capture, and on-screen balance reading," iVerify said. "It targets crypto wallets and banking apps after installation, while the delivery app can use an unrelated theme." Rust backdoor tied to ransomware C2Looper Likely Used by Ransomware Group A new Rust-based malware family dubbed C2Looper is likely leveraged by a ransomware-related threat actor and delivered to victims through a multi-stage ClickFix infection chain. Zscaler ThreatLabz said it discovered the malware in July 2026. "C2Looper supports typical backdoor commands including remote shell execution, reconnaissance, and deploying additional malware tooling," Zscaler said. "C2Looper dynamically resolves Windows APIs and encrypts strings." There also exists a variant with additional features and capabilities, including the use of GitHub for command-and-control (C2) communications. 296,000 IoT devices compromised Dysphoria Botnet Targets IoT Devices Nearly 296,000 devices have been compromised by a botnet named Dysphoria. "Dysphoria targets IoT devices and its primary function appears to be for use in DDoS-attacks," the Shadowserver Foundation said. "Recently the botnet has gotten residential proxy functionality." C2 moves onto Polygon Aeternum Pivots to EtherHiding A recently discovered C++ botnet loader called Aeternum has shifted its C2 infrastructure entirely to the public Polygon blockchain. "Instead of relying on centralized servers or domains, threat actors operate Aeternum by writing encrypted and plaintext instructions directly using smart contracts," Palo Alto Networks Unit 42 said. "Infected devices continuously query public remote procedure call (RPC) endpoints to retrieve and execute these on-chain commands. The Aeternum botnet uses decentralized networks and evasion techniques, such as virtual machine detection and antivirus scanning, to operate effectively. This combination establishes a highly resilient, low-cost threat that complicates existing law enforcement takedown methods." AI enters botnet workflows ToxNetV2 Botnet Integrates AI into Decision Workflows An AArch64 Linux peer-to-peer botnet called ToxNetV2 has integrated a large language model (LLM) into the operational workflow of its controller. The controller communicates with NVIDIA NIM using the z-ai/glm-5.2 model, becoming a part of a feedback loop that determines how its capabilities can be put to use on a given machine based on information about the infected environment. "The controller collects host and botnet telemetry, sends that context to NVIDIA NIM, parses selected model responses into structured actions, and queues those actions for operator approval," Joe Security said. "The system is not fully autonomous or self-modifying. The operator remains the final approval point for its higher-impact AI-generated actions. Once approved, however, those actions can reach local command execution, file writes, remote SSH, persistent state, and a compilation workflow." According to the cybersecurity company, the AI subsystem resides within a broader Tox-based botnet featuring encrypted peer-to-peer C2, host-management capabilities, scanner workers, self-propagation logic, and 17 network-attack launchers. Two stealers target credentials Phantom Stealer and Salat Stealer Detailed An information stealer called Phantom Stealer is designed to collect browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and detailed system fingerprints. "Since its appearance, Phantom Stealer has been observed in multiple campaigns targeting users across different countries, frequently distributed through phishing lures, crack

Indicators of Compromise

  • malware — Octagon

Entities

ShinyHunters (threat_actor)SharePoint (product)ReliaQuest (vendor)IoT (technology)MFA push abuse (technology)Electron (product)